Vulnerabilidades em HCL Software

355 resultados
Análise Vexday

Com 334 CVEs catalogadas e nenhuma registrada no catálogo de exploração ativa da CISA (KEV), o perfil de risco imediato da HCL Software situa-se abaixo da média geral do catálogo, o que sugere pressão operacional menor em termos de resposta emergencial. No entanto, a presença de 10 vulnerabilidades de severidade crítica exige atenção contínua, ainda que nenhuma delas possua prova de conceito pública conhecida no momento. A CVE mais perigosa atualmente apontada é a CVE-2023-37536, com escore EPSS de 0,0138, indicando probabilidade de exploração relativamente baixa, mas não desprezível dentro do horizonte de monitoramento. O tipo de falha mais recorrente — CWE-79 (Cross-Site Scripting) — e o surgimento de 8 novas CVEs nos últimos 90 dias reforçam a necessidade de ciclos regulares de revisão, especialmente em componentes voltados à interface web.

CVE-2022-44752CRITICALHCL Domino is susceptible to a stack based buffer overflow vulnerability in wp6sr.dll in Micro Focus KeyViewEPSS 0.6%CVE-2022-44750CRITICALHCL Domino is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. EPSS 0.6%CVE-2022-44751CRITICALHCL Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyViewEPSS 0.6%CVE-2025-0255HIGHHCL DevOps Deploy / HCL Launch is susceptible to command injection vulnerabilityEPSS 0.6%CVE-2024-23540MEDIUMHCL BigFix Inventory is vulnerable to path traversalEPSS 0.6%CVE-2022-27546HIGHHCL iNotes is susceptible to a Reflected Cross-site Scripting (XSS) vulnerabilityEPSS 0.6%CVE-2023-37498HIGHHCL Unica Platform is vulnerable to a privilege escalation by unauthorized group assignationEPSS 0.6%CVE-2021-27788HIGHHCL Verse is susceptible to a Cross Site Scripting (XSS) vulnerabilityEPSS 0.6%CVE-2021-27779CRITICALA Security Misconfiguration vulnerability affects HCL VersionVault ExpressEPSS 0.6%CVE-2023-50347LOWInsecure SQL Interface affects HCL DRYiCE MyXalyticsEPSS 0.6%CVE-2021-27786MEDIUMHCL OneTest Server is vulnerable to Cross Origin Resource Sharing: Arbitrary Origin TrustedEPSS 0.6%CVE-2022-42445MEDIUMHCL Launch is vulnerable to Insufficiently Protected LDAP Search Credentials (CVE-2022-42445)EPSS 0.5%CVE-2021-27764HIGHHCL BigFix WebUI Cookie missing attributesEPSS 0.5%CVE-2023-37497HIGHAn XML External Entity (XXE) Injection Vulnerability affects HCL Unica Platform EPSS 0.5%CVE-2023-45724HIGHUnauthenticated File Upload affects DRYiCE MyXalyticsEPSS 0.5%CVE-2020-4084HCL Connections v5.5, v6.0, and v6.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript cEPSS 0.5%CVE-2023-37532MEDIUMA path traversal vulnerability affects HCL CommerceEPSS 0.5%CVE-2025-31995LOWHCL Unica MaxAI Workbench is vulnerable to improper input validationEPSS 0.5%CVE-2022-27558MEDIUMHCL iNotes is susceptible to a Broken Password Strength Checks vulnerability.EPSS 0.5%CVE-2022-27551MEDIUMHCL Launch could allow an authenticated user to obtain sensitive information (CVE-2022-27551)EPSS 0.5%